Compliance / CCPA/CPRA

California Consumer Privacy Act & California Privacy Rights Act for MSPs

California's general consumer-privacy law — distinct from student-specific state privacy statutes — giving California residents rights over their personal data and imposing security obligations on the businesses, and their vendors, that hold it.

Why this reaches an MSP, not just the client

CCPA/CPRA applies based on doing business with California residents and crossing revenue or data-volume thresholds, not on where a client is headquartered — a client well outside California can still be in scope, and CPRA's amendments specifically extend obligations to service providers and contractors with system access, which is exactly the MSP's role.

What the Nexus compliance module tracks

  • Posture tracked against CPRA's "reasonable security" expectations — access control, encryption, vendor oversight — with the same three-state model used across every framework here, not a one-time checklist
  • Evidence attached directly to the control it supports, kept distinguishable from the FERPA/COPPA and state student-privacy pages for a client whose data isn't student-specific
  • Consumer rights-request handling — access, deletion, opt-out of sale or sharing — tracked as its own control, separate from general access-control posture
  • A QBR rollup that separates CCPA/CPRA-driven gaps from other framework gaps, so a client doesn't have to untangle which regulation a finding belongs to

This describes what the module tracks against CCPA/CPRA — not a claim that Nexus or any client on it is certified or audited against it. See the compliance & QBR module for the full picture, or read the blog for more on how we think about compliance tooling.

Ready to see CCPA/CPRA posture tracked for real?

Join the design-partner cohort and we'll walk through the control mapping for your own clients.